Microsoft Visio vulnerabilities
54 known vulnerabilities affecting microsoft/visio.
Total CVEs
54
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
5
Severity breakdown
CRITICAL32HIGH19MEDIUM3
Vulnerabilities
Page 2 of 3
CVE-2011-1979P3CRITICALCVSS 9.3v2003v20072011-08-10
CVE-2011-1979 [CRITICAL] CWE-20 CVE-2011-1979: Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file
Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
nvd
CVE-2009-2504P3CRITICALCVSS 9.3v20022009-10-14
CVE-2009-2504 [CRITICAL] CWE-189 CVE-2009-2504: Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Fra
Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word
nvd
CVE-2011-0093P3CRITICALCVSS 9.3v2002v2003+1 more2011-02-10
CVE-2011-0093 [CRITICAL] CWE-94 CVE-2011-0093: ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures
ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Data Type Memory Corruption Vulnerability."
nvd
CVE-2009-2502P3HIGHCVSS 8.1v20022009-10-14
CVE-2009-2502 [HIGH] CWE-119 CVE-2009-2502: Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3,
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, an
nvd
CVE-2009-0095P3CRITICALCVSS 9.3v2002v2003+1 more2009-02-10
CVE-2009-0095 [CRITICAL] CWE-399 CVE-2009-0095: Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Vi
Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."
nvd
CVE-2009-0096P3CRITICALCVSS 9.3v2002v2003+1 more2009-02-10
CVE-2009-0096 [CRITICAL] CWE-399 CVE-2009-0096: Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operat
Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."
nvd
CVE-2008-1090P3CRITICALCVSS 9.3v2002v2003+3 more2008-04-08
CVE-2008-1090 [CRITICAL] CWE-399 CVE-2008-1090: Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows u
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
nvd
CVE-2008-1089P3CRITICALCVSS 9.3v2002v2003+3 more2008-04-08
CVE-2008-1089 [CRITICAL] CWE-94 CVE-2008-1089: Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows u
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
nvd
CVE-2012-1888P3CRITICALCVSS 9.3v20102012-08-15
CVE-2012-1888 [CRITICAL] CWE-119 CVE-2012-1888: Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to exe
Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability."
nvd
CVE-2009-0097P3CRITICALCVSS 9.3v2002v2003+1 more2009-02-10
CVE-2009-0097 [CRITICAL] CWE-399 CVE-2009-0097: Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio
Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."
nvd
CVE-2009-2528P3CRITICALCVSS 9.3v20022009-10-14
CVE-2009-2528 [CRITICAL] CWE-94 CVE-2009-2528: GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Ta
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability."
nvd
CVE-2015-2503P3CRITICALCVSS 9.3v2007v2010+2 more2015-11-11
CVE-2015-2503 [CRITICAL] CWE-264 CVE-2015-2503: Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3,
Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2007 IME (Japanese) SP3, Access 2010 SP2, Excel 2010 SP2, InfoPath 2010 SP2, OneNote 2010 SP2, PowerPoint 2010 SP2, Project 2010 SP2, Publisher 2010 SP2, Visio 2010 SP2, Word
nvd
CVE-2010-0254P3HIGHCVSS 7.6v2002v2003+1 more2010-04-14
CVE-2010-0254 [HIGH] CWE-94 CVE-2010-0254: Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attribute
Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulnerability."
nvd
CVE-2020-0760P3HIGHCVSS 8.8v2010v2013+1 more2020-04-15
CVE-2020-0760 [HIGH] CVE-2020-0760: A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type l
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.
nvd
CVE-2006-5574P3CRITICALCVSS 9.3v20032006-12-31
CVE-2006-5574 [CRITICAL] CVE-2006-5574: Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and t
Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly parsed.
nvd
CVE-2016-3364P3HIGHCVSS 7.8v20162016-09-14
CVE-2016-3364 [HIGH] CWE-119 CVE-2016-3364: Microsoft Visio 2016 allows remote attackers to execute arbitrary code via a crafted document, aka "
Microsoft Visio 2016 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2006-3864P3CRITICALCVSS 9.3v20022006-10-10
CVE-2006-3864 [CRITICAL] CVE-2006-3864: Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoin
Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow)
nvd
CVE-2010-0256P3HIGHCVSS 7.6v2002v2003+1 more2010-04-14
CVE-2010-0256 [HIGH] CWE-94 CVE-2010-0256: Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecif
Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memory Corruption Vulnerability."
nvd
CVE-2007-0936P3CRITICALCVSS 9.3v20022007-06-12
CVE-2007-0936 [CRITICAL] CVE-2007-0936: Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to
Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."
nvd
CVE-2007-0934P3CRITICALCVSS 9.3v20022007-06-12
CVE-2007-0934 [CRITICAL] CVE-2007-0934: Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute a
Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.
nvd